annotate alert_rules.py @ 27:eec015e90818

reformat
author drewp@bigasterisk.com
date Thu, 29 Jun 2023 14:12:22 -0700
parents b15cfe483964
children e114edff93dc
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
23
drewp@bigasterisk.com
parents:
diff changeset
1 """
drewp@bigasterisk.com
parents:
diff changeset
2 pdm run invoke push-config
drewp@bigasterisk.com
parents:
diff changeset
3
drewp@bigasterisk.com
parents:
diff changeset
4 docs: https://prometheus.io/docs/prometheus/latest/configuration/alerting_rules/
drewp@bigasterisk.com
parents:
diff changeset
5 "Whenever the alert expression results in one or more vector
drewp@bigasterisk.com
parents:
diff changeset
6 elements at a given point in time, the alert counts as active for
drewp@bigasterisk.com
parents:
diff changeset
7 these elements' label sets."
drewp@bigasterisk.com
parents:
diff changeset
8 also https://www.metricfire.com/blog/top-5-prometheus-alertmanager-gotchas/#Missing-metrics
drewp@bigasterisk.com
parents:
diff changeset
9
drewp@bigasterisk.com
parents:
diff changeset
10 """
drewp@bigasterisk.com
parents:
diff changeset
11
drewp@bigasterisk.com
parents:
diff changeset
12 import json
drewp@bigasterisk.com
parents:
diff changeset
13
drewp@bigasterisk.com
parents:
diff changeset
14
drewp@bigasterisk.com
parents:
diff changeset
15 def k8sRules():
drewp@bigasterisk.com
parents:
diff changeset
16 # from https://awesome-prometheus-alerts.grep.to/rules.html
drewp@bigasterisk.com
parents:
diff changeset
17 return [
drewp@bigasterisk.com
parents:
diff changeset
18 {
drewp@bigasterisk.com
parents:
diff changeset
19 "alert": "PrometheusTargetMissing",
drewp@bigasterisk.com
parents:
diff changeset
20 "expr": "up == 0",
drewp@bigasterisk.com
parents:
diff changeset
21 "for": "0m",
drewp@bigasterisk.com
parents:
diff changeset
22 "labels": {"severity": "critical"},
drewp@bigasterisk.com
parents:
diff changeset
23 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
24 "summary": "Prometheus target missing (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
25 "description": "A Prometheus target has disappeared. An exporter might be crashed.\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
26 },
drewp@bigasterisk.com
parents:
diff changeset
27 },
drewp@bigasterisk.com
parents:
diff changeset
28 {
drewp@bigasterisk.com
parents:
diff changeset
29 "alert": "KubernetesMemoryPressure",
drewp@bigasterisk.com
parents:
diff changeset
30 "expr": 'kube_node_status_condition{condition="MemoryPressure",status="true"} == 1',
drewp@bigasterisk.com
parents:
diff changeset
31 "for": "2m",
drewp@bigasterisk.com
parents:
diff changeset
32 "labels": {"severity": "critical"},
drewp@bigasterisk.com
parents:
diff changeset
33 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
34 "summary": "Kubernetes memory pressure (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
35 "description": "{{ $labels.node }} has MemoryPressure condition\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
36 },
drewp@bigasterisk.com
parents:
diff changeset
37 },
drewp@bigasterisk.com
parents:
diff changeset
38 {
drewp@bigasterisk.com
parents:
diff changeset
39 "alert": "KubernetesDiskPressure",
drewp@bigasterisk.com
parents:
diff changeset
40 "expr": 'kube_node_status_condition{condition="DiskPressure",status="true"} == 1',
drewp@bigasterisk.com
parents:
diff changeset
41 "for": "2m",
drewp@bigasterisk.com
parents:
diff changeset
42 "labels": {"severity": "critical"},
drewp@bigasterisk.com
parents:
diff changeset
43 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
44 "summary": "Kubernetes disk pressure (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
45 "description": "{{ $labels.node }} has DiskPressure condition\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
46 },
drewp@bigasterisk.com
parents:
diff changeset
47 },
drewp@bigasterisk.com
parents:
diff changeset
48 {
drewp@bigasterisk.com
parents:
diff changeset
49 "alert": "KubernetesOutOfDisk",
drewp@bigasterisk.com
parents:
diff changeset
50 "expr": 'kube_node_status_condition{condition="OutOfDisk",status="true"} == 1',
drewp@bigasterisk.com
parents:
diff changeset
51 "for": "2m",
drewp@bigasterisk.com
parents:
diff changeset
52 "labels": {"severity": "critical"},
drewp@bigasterisk.com
parents:
diff changeset
53 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
54 "summary": "Kubernetes out of disk (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
55 "description": "{{ $labels.node }} has OutOfDisk condition\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
56 },
drewp@bigasterisk.com
parents:
diff changeset
57 },
drewp@bigasterisk.com
parents:
diff changeset
58 {
drewp@bigasterisk.com
parents:
diff changeset
59 "alert": "KubernetesJobFailed",
drewp@bigasterisk.com
parents:
diff changeset
60 "expr": "kube_job_status_failed > 0",
drewp@bigasterisk.com
parents:
diff changeset
61 "for": "0m",
drewp@bigasterisk.com
parents:
diff changeset
62 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
63 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
64 "summary": "Kubernetes Job failed (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
65 "description": "Job {{$labels.namespace}}/{{$labels.exported_job}} failed to complete\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
66 },
drewp@bigasterisk.com
parents:
diff changeset
67 },
drewp@bigasterisk.com
parents:
diff changeset
68 {
drewp@bigasterisk.com
parents:
diff changeset
69 "alert": "KubernetesPodCrashLooping",
drewp@bigasterisk.com
parents:
diff changeset
70 "expr": "increase(kube_pod_container_status_restarts_total[1m]) > 3",
drewp@bigasterisk.com
parents:
diff changeset
71 "for": "2m",
drewp@bigasterisk.com
parents:
diff changeset
72 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
73 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
74 "summary": "Kubernetes pod crash looping (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
75 "description": "Pod {{ $labels.pod }} is crash looping\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
76 },
drewp@bigasterisk.com
parents:
diff changeset
77 },
drewp@bigasterisk.com
parents:
diff changeset
78 {
drewp@bigasterisk.com
parents:
diff changeset
79 "alert": "KubernetesClientCertificateExpiresNextWeek",
drewp@bigasterisk.com
parents:
diff changeset
80 "expr": 'apiserver_client_certificate_expiration_seconds_count{job="apiserver"} > 0 and histogram_quantile(0.01, sum by (job, le) (rate(apiserver_client_certificate_expiration_seconds_bucket{job="apiserver"}[5m]))) < 7*24*60*60',
drewp@bigasterisk.com
parents:
diff changeset
81 "for": "0m",
drewp@bigasterisk.com
parents:
diff changeset
82 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
83 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
84 "summary": "Kubernetes client certificate expires next week (instance {{ $labels.instance }})",
drewp@bigasterisk.com
parents:
diff changeset
85 "description": "A client certificate used to authenticate to the apiserver is expiring next week.\n VALUE = {{ $value }}",
drewp@bigasterisk.com
parents:
diff changeset
86 },
drewp@bigasterisk.com
parents:
diff changeset
87 },
drewp@bigasterisk.com
parents:
diff changeset
88 {
drewp@bigasterisk.com
parents:
diff changeset
89 "alert": "container_waiting",
drewp@bigasterisk.com
parents:
diff changeset
90 "expr": "sum by (container)(kube_pod_container_status_waiting!=0)",
drewp@bigasterisk.com
parents:
diff changeset
91 "for": "2m",
drewp@bigasterisk.com
parents:
diff changeset
92 },
drewp@bigasterisk.com
parents:
diff changeset
93 ]
drewp@bigasterisk.com
parents:
diff changeset
94
drewp@bigasterisk.com
parents:
diff changeset
95
drewp@bigasterisk.com
parents:
diff changeset
96 def allRules():
drewp@bigasterisk.com
parents:
diff changeset
97 return {
drewp@bigasterisk.com
parents:
diff changeset
98 "groups": [
drewp@bigasterisk.com
parents:
diff changeset
99 {
drewp@bigasterisk.com
parents:
diff changeset
100 "name": "k8s",
drewp@bigasterisk.com
parents:
diff changeset
101 "rules": k8sRules(),
drewp@bigasterisk.com
parents:
diff changeset
102 },
drewp@bigasterisk.com
parents:
diff changeset
103 #
drewp@bigasterisk.com
parents:
diff changeset
104 # any presence of starlette_request_duration_seconds_created{app_name="starlette",method="GET",path="/",status_code="200"} 1.6460176156784086e+09 means someone forgot to set app name
drewp@bigasterisk.com
parents:
diff changeset
105 {
drewp@bigasterisk.com
parents:
diff changeset
106 "name": "Outages",
drewp@bigasterisk.com
parents:
diff changeset
107 "rules": [
drewp@bigasterisk.com
parents:
diff changeset
108 {
drewp@bigasterisk.com
parents:
diff changeset
109 "alert": "powereagleStalled",
drewp@bigasterisk.com
parents:
diff changeset
110 "expr": "rate(house_power_w[100m]) == 0",
drewp@bigasterisk.com
parents:
diff changeset
111 "for": "0m",
drewp@bigasterisk.com
parents:
diff changeset
112 "labels": {"severity": "losingData"},
drewp@bigasterisk.com
parents:
diff changeset
113 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
114 "summary": "power eagle data stalled",
drewp@bigasterisk.com
parents:
diff changeset
115 "description": "logs at https://bigasterisk.com/k/clusters/local/namespaces/default/deployments/power-eagle/logs",
drewp@bigasterisk.com
parents:
diff changeset
116 },
drewp@bigasterisk.com
parents:
diff changeset
117 },
drewp@bigasterisk.com
parents:
diff changeset
118 {
drewp@bigasterisk.com
parents:
diff changeset
119 "alert": "powereagleAbsent",
drewp@bigasterisk.com
parents:
diff changeset
120 "expr": "absent_over_time(house_power_w[5m])",
drewp@bigasterisk.com
parents:
diff changeset
121 "for": "2m",
drewp@bigasterisk.com
parents:
diff changeset
122 "labels": {"severity": "losingData"},
drewp@bigasterisk.com
parents:
diff changeset
123 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
124 "summary": "power eagle data missing",
drewp@bigasterisk.com
parents:
diff changeset
125 "description": "logs at https://bigasterisk.com/k/clusters/local/namespaces/default/deployments/power-eagle/logs",
drewp@bigasterisk.com
parents:
diff changeset
126 },
drewp@bigasterisk.com
parents:
diff changeset
127 },
drewp@bigasterisk.com
parents:
diff changeset
128 {
drewp@bigasterisk.com
parents:
diff changeset
129 "alert": "absent_zigbee",
drewp@bigasterisk.com
parents:
diff changeset
130 "expr": 'absent(container_last_seen{container="zigbee2mqtt"})',
drewp@bigasterisk.com
parents:
diff changeset
131 },
drewp@bigasterisk.com
parents:
diff changeset
132 {
drewp@bigasterisk.com
parents:
diff changeset
133 "alert": "net_routes_sync",
drewp@bigasterisk.com
parents:
diff changeset
134 "expr": 'rate(starlette_request_duration_seconds_count{app_name="net_routes",path="/routes"}[5m]) < 1/70',
drewp@bigasterisk.com
parents:
diff changeset
135 "for": "10m",
drewp@bigasterisk.com
parents:
diff changeset
136 "labels": {"severity": "houseUsersAffected"},
drewp@bigasterisk.com
parents:
diff changeset
137 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
138 "summary": "net_routes is not getting regular updates"
drewp@bigasterisk.com
parents:
diff changeset
139 },
drewp@bigasterisk.com
parents:
diff changeset
140 },
drewp@bigasterisk.com
parents:
diff changeset
141 ],
drewp@bigasterisk.com
parents:
diff changeset
142 },
drewp@bigasterisk.com
parents:
diff changeset
143 {
drewp@bigasterisk.com
parents:
diff changeset
144 "name": "alerts",
drewp@bigasterisk.com
parents:
diff changeset
145 "rules": [
drewp@bigasterisk.com
parents:
diff changeset
146 {
drewp@bigasterisk.com
parents:
diff changeset
147 "alert": "kube_node_status_bad_condition",
drewp@bigasterisk.com
parents:
diff changeset
148 "for": "2h",
drewp@bigasterisk.com
parents:
diff changeset
149 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
150 "expr": 'kube_node_status_condition{condition=~".*Pressure",status="true"} > 0',
drewp@bigasterisk.com
parents:
diff changeset
151 },
drewp@bigasterisk.com
parents:
diff changeset
152 {
drewp@bigasterisk.com
parents:
diff changeset
153 "alert": "housePower",
drewp@bigasterisk.com
parents:
diff changeset
154 "for": "24h",
drewp@bigasterisk.com
parents:
diff changeset
155 "labels": {"severity": "waste"},
drewp@bigasterisk.com
parents:
diff changeset
156 "expr": "house_power_w > 4000",
drewp@bigasterisk.com
parents:
diff changeset
157 "annotations": {"summary": "house power usage over 4KW"},
drewp@bigasterisk.com
parents:
diff changeset
158 },
drewp@bigasterisk.com
parents:
diff changeset
159 {
drewp@bigasterisk.com
parents:
diff changeset
160 "alert": "host_root_fs_space_low",
drewp@bigasterisk.com
parents:
diff changeset
161 "for": "20m",
drewp@bigasterisk.com
parents:
diff changeset
162 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
163 "expr": 'disk_free{path="/"} < 20G',
drewp@bigasterisk.com
parents:
diff changeset
164 },
drewp@bigasterisk.com
parents:
diff changeset
165 {
drewp@bigasterisk.com
parents:
diff changeset
166 "alert": "zpool_space_low",
drewp@bigasterisk.com
parents:
diff changeset
167 "for": "20m",
drewp@bigasterisk.com
parents:
diff changeset
168 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
169 "expr": 'last_over_time(zfs_pool_free_bytes{pool="stor7"}[1h]) < 100G',
drewp@bigasterisk.com
parents:
diff changeset
170 },
drewp@bigasterisk.com
parents:
diff changeset
171 {
drewp@bigasterisk.com
parents:
diff changeset
172 "alert": "zpool_device_error_count",
drewp@bigasterisk.com
parents:
diff changeset
173 "for": "20m",
drewp@bigasterisk.com
parents:
diff changeset
174 "labels": {"severity": "warning"},
26
b15cfe483964 rm bogus summaries
drewp@bigasterisk.com
parents: 23
diff changeset
175 "expr": 'increase(zpool_device_error_count[2h]) > 0',
23
drewp@bigasterisk.com
parents:
diff changeset
176 },
drewp@bigasterisk.com
parents:
diff changeset
177 {
drewp@bigasterisk.com
parents:
diff changeset
178 "alert": "disk_week_incr",
drewp@bigasterisk.com
parents:
diff changeset
179 "for": "20m",
drewp@bigasterisk.com
parents:
diff changeset
180 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
181 "expr": 'round(increase(disk_used{path=~"/my/.*"}[1d])/1M) > 5000',
drewp@bigasterisk.com
parents:
diff changeset
182 "annotations": {"summary": "high mb/week on zfs dir"},
drewp@bigasterisk.com
parents:
diff changeset
183 },
drewp@bigasterisk.com
parents:
diff changeset
184 {
drewp@bigasterisk.com
parents:
diff changeset
185 "alert": "high_logging",
drewp@bigasterisk.com
parents:
diff changeset
186 "for": "20m",
drewp@bigasterisk.com
parents:
diff changeset
187 "labels": {"severity": "waste"},
drewp@bigasterisk.com
parents:
diff changeset
188 "expr": "sum by (container) (rate(kubelet_container_log_filesystem_used_bytes[3h])) > 4k",
drewp@bigasterisk.com
parents:
diff changeset
189 "annotations": {"summary": "high log output rate"},
drewp@bigasterisk.com
parents:
diff changeset
190 },
drewp@bigasterisk.com
parents:
diff changeset
191 {
drewp@bigasterisk.com
parents:
diff changeset
192 "alert": "stale_process",
drewp@bigasterisk.com
parents:
diff changeset
193 "for": "1d",
drewp@bigasterisk.com
parents:
diff changeset
194 "labels": {"severity": "dataRisk"},
drewp@bigasterisk.com
parents:
diff changeset
195 "expr": "round((time() - filestat_modification_time/1e9) / 86400) > 14",
drewp@bigasterisk.com
parents:
diff changeset
196 "annotations": {"summary": "process time is old"},
drewp@bigasterisk.com
parents:
diff changeset
197 },
drewp@bigasterisk.com
parents:
diff changeset
198 {
drewp@bigasterisk.com
parents:
diff changeset
199 "alert": "starlette",
drewp@bigasterisk.com
parents:
diff changeset
200 "for": "1m",
drewp@bigasterisk.com
parents:
diff changeset
201 "labels": {"severity": "fix"},
drewp@bigasterisk.com
parents:
diff changeset
202 "expr": 'starlette_request_duration_seconds_created{app_name="starlette"}',
drewp@bigasterisk.com
parents:
diff changeset
203 "annotations": {"summary": "set starlette app name"},
drewp@bigasterisk.com
parents:
diff changeset
204 },
drewp@bigasterisk.com
parents:
diff changeset
205 {
drewp@bigasterisk.com
parents:
diff changeset
206 "alert": "ssl_certs_expiring_soon",
drewp@bigasterisk.com
parents:
diff changeset
207 "expr": "min((min_over_time(probe_ssl_earliest_cert_expiry[1d])-time())/86400) < 10",
drewp@bigasterisk.com
parents:
diff changeset
208 "labels": {"severity": "warning"},
drewp@bigasterisk.com
parents:
diff changeset
209 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
210 "summary": "cert expiring soon. See https://bigasterisk.com/grafana/d/z1YtDa3Gz/certs?orgId=1\nVALUE = {{ $value }}"
drewp@bigasterisk.com
parents:
diff changeset
211 },
drewp@bigasterisk.com
parents:
diff changeset
212 },
drewp@bigasterisk.com
parents:
diff changeset
213 ],
drewp@bigasterisk.com
parents:
diff changeset
214 },
drewp@bigasterisk.com
parents:
diff changeset
215 ]
drewp@bigasterisk.com
parents:
diff changeset
216 }
drewp@bigasterisk.com
parents:
diff changeset
217
drewp@bigasterisk.com
parents:
diff changeset
218
drewp@bigasterisk.com
parents:
diff changeset
219 def _runJson(ctx, cmd):
drewp@bigasterisk.com
parents:
diff changeset
220 return json.loads(ctx.run(cmd, hide="stdout").stdout)
drewp@bigasterisk.com
parents:
diff changeset
221
drewp@bigasterisk.com
parents:
diff changeset
222
drewp@bigasterisk.com
parents:
diff changeset
223 def hostsExpectedOnline(ctx):
drewp@bigasterisk.com
parents:
diff changeset
224 return _runJson(ctx, "cd /my/serv/lanscape; pdm run python hosts_expected_online.py")
drewp@bigasterisk.com
parents:
diff changeset
225
drewp@bigasterisk.com
parents:
diff changeset
226
drewp@bigasterisk.com
parents:
diff changeset
227 def expectedK8sNodes(ctx):
drewp@bigasterisk.com
parents:
diff changeset
228 getNode = _runJson(ctx, "kubectl get node -o json")
drewp@bigasterisk.com
parents:
diff changeset
229 hosts = [item["metadata"]["name"] for item in getNode["items"]]
drewp@bigasterisk.com
parents:
diff changeset
230 optionalHosts = {'slash'}
drewp@bigasterisk.com
parents:
diff changeset
231 return {
drewp@bigasterisk.com
parents:
diff changeset
232 "groups": [
drewp@bigasterisk.com
parents:
diff changeset
233 {
drewp@bigasterisk.com
parents:
diff changeset
234 "name": "k8s_expected_nodes",
drewp@bigasterisk.com
parents:
diff changeset
235 "rules": [
drewp@bigasterisk.com
parents:
diff changeset
236 {
drewp@bigasterisk.com
parents:
diff changeset
237 "alert": "kube_node_log_size_report_" + h,
drewp@bigasterisk.com
parents:
diff changeset
238 "expr": 'absent(kubelet_container_log_filesystem_used_bytes{instance="%s"})'
drewp@bigasterisk.com
parents:
diff changeset
239 % h,
drewp@bigasterisk.com
parents:
diff changeset
240 "for": "1h",
drewp@bigasterisk.com
parents:
diff changeset
241 "annotations": {
drewp@bigasterisk.com
parents:
diff changeset
242 "summary": f"no recent k8s log size report from host {h}"
drewp@bigasterisk.com
parents:
diff changeset
243 },
drewp@bigasterisk.com
parents:
diff changeset
244 }
drewp@bigasterisk.com
parents:
diff changeset
245 for h in hosts if not h in optionalHosts
drewp@bigasterisk.com
parents:
diff changeset
246 ],
drewp@bigasterisk.com
parents:
diff changeset
247 }
drewp@bigasterisk.com
parents:
diff changeset
248 ]
drewp@bigasterisk.com
parents:
diff changeset
249 }